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Claims : 

1. A system comprising: 

a participant subsystem that is authorized to anonymously 
participate in a plurality of sessions using secret 
information provided by a manager subsystem; and 
5 a reception subsystem that determines whether it is 

acceptable for the participant subsystem to participate in a 
session, 

wherein 

the participant subsystem comprises: 
10 an anonymous signing section for authorizing 

individual data using the secret information depending on 
session-related information to produce anonymous 
participation data with anonymous signature, and 
the reception subsystem comprises ; 
15 an anonymous signature determining jsection for 

determining whether received data is anonymous participation 
data with anonymous signature authorized by the participant 
subsystem; and 

a sender match determining section for determining 
20 whether anonymous signatures of arbitrary two pieces of 
anonymous participation data are signed by an identical 
participant subsystem. 
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2. The system according to claim 1, wherein the 
anonymous signature includes data that is generated by a 
predetermined expression using the session-related 
information and the secret information, wherein the sender 
5 match determining section checks the data included in the 
anonymous signature of received anonymous participation data. 



3. The system according to claim 2, wherein the 
predetermined expression is represented by raising a 
session- dependent base to a power that is dependent on the 
secret Information. 

4. The system according to claim 1, wherein the 
anonymous signing section authorizes the individual data based 
on a group signature scheme. 

5- The system according to claim 1, wherein the 
15 anonymous signing section authorizes the individual data based 
on an escrowed identity scheme. 




6 . The system according to claim 1 , wherein the 
anonymous signing section comprises: 

a generator creating section for creating a 
20 session-dependent generator depending on the session-related 
information; 
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a group signing section for signing the individual 
data using the session-dependent generator and the secret 
information to produce anonymous participation data, wherein 
the anonymous participation data includes data obtained by 
5 raising the session -dependent generator to a power determined 
by the secret information; and 

a linkage data generating section for generating 
linkage data indicating a relationship among the session- 
dependent generator and a generator determined by the 
10 individual data and/or the session-related information. 



7 . The system according to claim 6 , wherein the secret 
information is represented by {x, y, v) that satisfies: v = 
(y + 6) I/# mod n 9 where y = cf mod n t n is a product of two prime 
numbers as used in the RSA cryptography, g is a generator that 
15 generates a cyclic group of order n, a is an integer mutually 
prime to n, & is an integer mutually prime to the Euler number 
of n t and 5 is a constant other than 1, 

the generator creating section creates a 
session-dependent generator g A corresponding to a session A 
20 and a generator g m is generated based on the individual data 
m and/or the session A. 

the group signing section sets z - gf and generates 
a first proof statement 
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proving the knowledge of a satisfying z = g A ^ a ^ ' a second 
proof statement 

V % = SKRQOTLOGU*^/,^, <*)[{*: x*g* = «, { P e) I(l) 
proving the knowledge of 0 satisfying z*& A h = g r A (fi 

the linkage data generating section sets z 1 * 
and generates a third proof statement 

proving the knowledge of z x and s have the same power to the 
bases g m and g Ai respectively, 

wherein the anonymous participation data is defined 
as {A, m t z t V x . V 2 , V 3 ) , 

8 . The system according to claim 7 , wherein 
the anonymous signature determining section checks 

V lr V 2 , and v 3 of the anonymous participation data to determine 
15 whether received data is anonymous participation data with 
anonymous signature authorized by the participant subsystem, 
and 

the sender match determining section checks z of the 
anonymous participation data to determine whether anonymous 
20 signatures of arbitrary two pieces of anonymous participation 
data are signed by an identical participant subsystem. 

9. The system according to claim 1, wherein the 
anonymous signing section comprises : 
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a generator creating section for creating a 
generator depending on the session-related information; 

a group signing section for signing the individual 
data using the generator and the secret information to produce 
5 anonymous participation data, wherein the anonymous 

participation data includes data obtained by raising the 
session-dependent generator to a power determined by the 
secret information. 

2 10 • T ** e system according to claim 9 , wherein the secret 

01 10 information is represented by {x t y, v) that satisfies: v - 
; fi (y + 8) 1/ "mod n, where y = a'modzi, the individual data is denoted 

by m, a is a product of two prime numbers as used in the RSA 
l2 cryptography, g is a generator that generates a cyclic group 

I?: of order n, a is an integer mutually prime to n, & is an integer 

^ 15 mutually prime to the Euler number of n t and 6 is a constant 
other than 1 , 

the generator creating section creates a 
session- dependent generator g A corresponding to a session A. 

the group signing section sets z = g/ and generates 
20 a first proof statement 

V 1 = SKLOGLOG(j3r,<^,<2) [a : jr - gS a ^ 3 (m) 
proving the knowledge of a satisfying 2 = g^S^ * and a second 
proof statement 

V 1 = SKROOTLOGU*^^,e)[(3: x*g A * = ^<P # )](m) 
25 proving the )cnowledge of p satisfying z*g£ « g A ^^K 
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wherein the anonymous participation data 13 is 
designated as {A, n? r z. V lw V 2 ) . 

11. The system according to claim 10, wherein 
the anonymous signature determining section checks 

v lf and v 2 of the anonymous participation data to determine 
whether received data is anonymous participation data with 
anonymous signature authorized hy the participant subsystem, 
and 

the sender match determining section checks z of the 
anonymous participation data to determine whether anonymous 
signatures of arbitrary two pieces of anonymous participation 
data are signed by an identical participant subsystem. 

12. The system according to claim 1, wherein the 
anonymous signing section comprises: 

15 a generator creating section for creating a 

session -dependent generator depending on the session-related 
information; 

an escrow identifying section for signing the 
individual data using the session -dependent generator and the 

20 secret information to produce anonymous participation data, 
wherein the anonymous participation data includes data 
obtained by raising the session-dependent generator to a power 
determined by the secret information; and 
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a linkage data generating section for generating 
linkage data indicating a relationship among the session- 
dependent generator and a generator determined by the 
individual data and/or the session-related information. 

5 13 - The system according to claim 12 , wherein the secret 

information is represented by {a, b) that satisfies 
b « (a" - o) 1/e mod n, where n is a product of two prime numbers 
as used in the RSA cryptography, ^isa generator that generates 
a cyclic group of order n r a is an Integer mutually prime to 
10 J3, e is an integer mutually prime to the Euler number of n, 
and 6 Is a constant other than 1, 

the generator creating section creates a 
session-dependent generator g A corresponding to a session A 
and a generator g m is generated based on the individual data 
15 J77 and/or the session A, 

the escrow identifying section sets z a - si ta * J 
generates a first proof statement 

V 1 « SKROOTLOG @) [a: z 0 =» ^(^)](1) 
proving the knowledge of a satisfying z g = g^^K and sets z * 
20 = ffA^") and generates a second proof statement 
V 2 = SKROOTLOG z b = ^^KD 

proving the knowledge of 0. satisfying * b = g^^K and 

the linkage data generating section sets z a = gj-**} 
and generates a third proof statement 
25 V, = SKREP(zJz af ff M /g A )ltt zjz 9 = (s^/tf.) 1 ] ( U 
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proving the knowledge of z^ and z G having the same power to the 
bases gr A and g mt respectively, 

wherein the anonymous participation data is defined 
as (A, m, z a , z b , z 0 , V x , V 2 , V % ) . 

14. The system according to claim 13 , wherein 
the anonymous signature determining section 

determines whether zjz b = is satisfied and checks V xt V?, 
and V z of the anonymous participation data to determine whether 
received data is anonymous participation data with anonymous 
signature authorized by the participant subsystem, and 

the sender match determining section checks one of 
z 9 and z fy of the anonymous participation data to determine 
whether anonymous signatures of arbitrary two pieces of 
anonymous participation data are signed by an identical 
participant subsystem. 

15 . The system according to claim 1 , wherein the 
anonymous signing section comprises: 

a generator creating section for creating a 
session-dependent generator depending on the session-related 
20 information? and 

an escrow identifying section for signing the 
individual data using the session-dependent generator and the 
secret information to produce anonymous participation data, 
wherein the anonymous participation data includes data 
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obtained by raising the session- dependent generator to a power 
determined by the secret information » 

16. The system according to claim 15, wherein the secret 
information is represented by (a, b) that satisfies 
5 b = (a* - 5) l/a mod n. where iJisa product of two prime numbers 
as used in the RSA cryptography, ^isa generator that generates 
a cyclic group of order n w a is an integer mutually prime to 
^ n, e is an integer mutually prime to the Euler number of n, 

and S is a constant other than 1, 
]*\ 1° the generator creating section creates a 

m session -dependent generator g A corresponding to a session A, 

the escrow identifying section sets z m - &A^ a *} an( * 
l2 generates a first proof statement 

jy V x = SKROOTLOC(^,^,a) [a: z a = 5i<**>](m) 

r: 15 proving the knowledge of a satisfying z a = * and sets z b 

* pJ 2 *") and generates a second proof statement 
V 2 = SKROOTLOG {2 bt ff A ,e)[$i z b = ^^°)j(m) 

> 

proving the knowledge of p satisfying ^ = , 

wherein the anonymous participation data is defined 
20 as {A. m. z a , z b . F 2 ) . 

17. The system according to claim 16, wherein 

the anonymous signature determining section 
determines whether zjz h « is satisfied and checks V x and 
V z of the anonymous participation data to determine whether 
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received, data is anonymous participation data with anonymous 
signature authorized by the participant subsystem, and 

the sender match determining section checks one of 
z a and & 0 of the anonymous participation data to determine 
5 whether anonymous signatures of arbitrary two pieces of 
anonymous participation data are signed by an identical 
participant subsystem. 

18. An anonymous participation authority management 
method for a system comprising; 
10 a participant subsystem that is authorized to anonymously 

participate in a plurality of sessions using secret 
information; and 

a reception subsystem that determines whether it is 
acceptable for the participant subsystem to participate in a 
15 session, 

the method comprising the steps of: 
at the participant subsystem. 

a) authorizing individual data using the secret 
information depending on session-related information to 

20 produce anonymous participation data with anonymous 
signature; 

at the reception subsystem, 

b) determining whether received data is anonymous 
participation data with anonymous signature authorized by the 

25 participant subsystem; and 
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c) determining whether anonymous signatures of 
arbitrary two pieces o£ anonymous participation data are 
signed by an identical participant subsystem. 

19. The method according to claim 18, wherein the 
5 anonymous signature includes data that is generated by a 

predetermined expression using the session-related 
information and the secret information, wherein the step (c) 
is performed by checking the data Included in the anonymous 
signature of received anonymous participation data. 

20. The method according to claim 19, wherein the 
predetermined expression is represented by raising a 
session -dependent base to a power that is dependent on the 
secret information. 

21* The method according to claim 18, wherein the step 
15 (a) comprises the steps ofi 

creating a session-dependent generator depending on 
the session-related information; 

signing the individual data using the session- 
dependent generator and the secret Information to produce 
20 anonymous participation data, wherein the anonymous 

participation data includes data obtained by raising the 
session -dependent generator to a power determined by the 
secret information; and 
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generating linkage data indicating a relationship 
among the session-dependent generator and a generator 
determined by the individual data and/or the session-related 
information . 

5 22. The method according to claim 18, wherein the step 

(a) comprises the steps of: 

creating a session-dependent generator depending on 
the session-related information; and 

signing the individual data using the sesslon- 
10 dependent generator and the secret information to produce 
anonymous participation data, wherein the anonymous 
participation data includes data obtained by raising the 
session-dependent generator to a power determined by the 
secret information. 



